Security Configuration Manager is an attack surface reduction tool for Windows Server 2008 SP2. It determines the minimum functionality required for a server’s role, and disables functionality that is not required. SCW does the following:
· Disables unneeded services
· Blocks unused ports
· Allows further address or security restrictions for ports that are left open
· Prohibits unnecessary IIS web extensions, if applicable
· Reduces protocol exposure to server message block (SMB), LanMan, and Lightweight Directory Access Protocol (LDAP)
NOTE: When using this procedure you must be aware that different options within ‘Security Configuration Manager’ will be required depending on the type of server you are building. This procedure details the configuration for the OCS EDGE servers only.
· To harden the server, the Security Configuration Wizard (SCW) needs to be run which allows you to create a security policy to be applied.
· Logon to the OCS EDGE server with the local admin account and launch Security Configuration Wizard via Administration Tools.
![clip_image002 clip_image002](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlfYW_Y7qI7fmgXJx4rMhOkr_nN1j7YoF-5xFr7v71DQ1ZK_QzH_yJMr0MEqaxkvPerKV-AK5f0cZqi2NSO8w1H2TYlokV_rRY66I8p5zZJQOHbDNaMbTzTtmGji_eu-76OUl0JypCFNTw/?imgmax=800)
· Select Next (click OK on the Access denied prompt)
![clip_image004 clip_image004](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiErtS7h-ke2JNr40Fq8k6gkkhyphenhyphengq2tnClpWW4LSaqVpUEMkVD5d7o17aNY9IJz0VmsrAeSM391It32GjB1NFtqV35OobHatzRoWqWdjh7zbvXTFrdSQ2INPa9HojA2hlJ6b7CMW_nSorYf/?imgmax=800)
· Select Create a new security policy and Next
![clip_image006 clip_image006](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWS1uh6HZ_WdiarhSAxsPDuIk6PsBtBk-igl7J6D6Ljg9oEAUTqfhls-YKJzOm7tkRHRW1Xyk1OzYGXLgLBI6-IhsdfHB8B13W5lGdgt7F9XojtkvLmzpuu_y5fncqj3QZbmCZArEpngiv/?imgmax=800)
· Add the server name you are applying the Security policy to and click Next.
![clip_image008 clip_image008](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbu3aRPr7KEJYdAWEXWaGXI_41HC0OyDF6XgS0PA3XhAmmK-9jv_mNDwC-Y-Nwnun3z3hUn9CP1DEsOWTamTW2QYUm6j50GVsDcxHuzNdbFQWHD2ew71SDJTqQYzK9DL6RCWFikmm07E5B/?imgmax=800)
· Next of the resulting screen.
![clip_image010 clip_image010](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEju2lZj8hfby0fqP1lzNWlEvedXceCVkmkykytnz3NuIhMolsDSgVFr_M4ThOHInJe4_T2qDkttY2W318VO5iMWrKeUydvFp8JqaOMB5-cSgtkbr8jcwSrbhyphenhyphenL-8o0SOFYerqLd5P2gEZvS/?imgmax=800)
· Next again.
![clip_image012 clip_image012](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOvKEi6lpyt0_7lLJiJPcx7oNp4QnpyYG7hFbrJcBDAfeZni2lTRpAwse7i2VPKC8NuUtCItIxNiPjAf2PalqbYgiNwLrpsNJLy6HfIW_ZLQt3-PcBoJ7SFIwjsi2YrrIDEOQeiwl3oP5H/?imgmax=800)
· Ensure the following installed roles are selected and click Next.
![clip_image014 clip_image014](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXld_Vd6MsQYbHvdsHowe5N0ya-RgP1IOO74FCqNv_BzxKPxbbviA8qKBZ28uurjfZmcrW700xxzFJZOEplBpT7LR1CBNiz-NAzbfGn1VqzMCfMYX2PoPqdZ8wIi1UIqsMLpX7lAjTvLML/?imgmax=800)
![clip_image016 clip_image016](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiI8NBBBNxeBspggFyvCC6DjJPg9x_z3dBAybQgIjJ78GdbfUsKIhbUCsi1J7_87CCQOkpUIxeJXoV8cDKEHnvtwlCElz7D161HFcZeyvCFLwKjdptPVxM1xglm8CACajWhvSDdlSXjY3P-/?imgmax=800)
· Ensure the following installed features are selected and click Next.
![clip_image018 clip_image018](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEIaSieJ25IfbBGMFO0KAWvbElcJ0nhQ5uQG1suXuGH3yNxruHD4aiRczcHTSjhXjU_RyassdTKijBBqEIGxHa8YENpcBdIGNEr8jeSoOzE-rRg2dbiIZq6yc9RSnWFNlAz6tJ31hEwkIq/?imgmax=800)
![clip_image020 clip_image020](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgL0zRW1d6pjt39IHc8AaeC_TPscksPD1_JG0jRgYg7Puyxg41CwPlW0mCNM1YFguTPGOs5AFXVZjjn7QHrYmXOjhx7ImJ9T0o-AyrmMMtLDRDb0bKHAn9FF51rn0ZxgUz1FSqr6g4njet0/?imgmax=800)
· Ensure the following installed options are selected and click Next.
![clip_image022 clip_image022](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyxrnkEnfqQuKGgFN66CpsBQQD_0TUuREnF7Ap7ksp5c2GyZc0oJq7b4wyqQ0xH6YUorj2RAJI0YqMg0tEinW9C55Gr24Y-wyevpseHFg5fETOylDI2YT4q68pgG1r6gGGrsXLnkaYeLZX/?imgmax=800)
![clip_image024 clip_image024](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgG4_RhvomzPCBthbL_rNTP2r_mq13L7HmDlF_orPx70e5KKiuV9HhIBPY51aG76b9dXEHThIsOr9YAafsyWl36nLGRozeyK2-wUesJVqimQQ6Ev5X1rGBvVbYVScufKFKIltjpJLUq2gy6/?imgmax=800)
![clip_image026 clip_image026](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIYBa5cw_uxi-MrtYWp73ixO55Y5Vfm8XhijU_qPIKhP3ESk7VClout2PHKKveWpZQz6t7fgA4kh9CVMjVXcJkX2XwK8SodBCQPwbmcnj5xkrpVYWmGgotmmq9o1oafL1vrrzJaTarbUd1/?imgmax=800)
![clip_image028 clip_image028](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFkbZ-kEOfBydPxp28UaWkjdH0zxhJe0gcsAajuaAOQgiDrAlLDu6VawrOVMFfIB3EVxh93JXXYbSAng3067f9mhzJcxMjbsLUBB3vtRgoCf0SJX3aZcKRA_v5JLBkO-bvIG0Zdp93eO52/?imgmax=800)
· Ensure the following additional services are selected and click Next
![clip_image030 clip_image030](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYAzO4dfYUVOyZLonGmcSGnxkHBXhnRnlER64lOlhQ4fouFtvqy2yd_HR4KCVJJB-zxE1gGUPo1dhlEDBwSOEXJ9zIxXiybp82YZqTnmBESc7U-9I0rdJbjpndLJpJqyMsWOG89ThbDizg/?imgmax=800)
![clip_image032 clip_image032](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4obbEAsDLnVKxYLviZi_n-qsVHYB-h0nRCyssy-i-U5h70ColnQrQbevyA9jGpvPbbPwcjI_PsACznlUjnSrxRCZLtRL2Lzk3ISh5dk1jhnGpavm-ZvI6-KND3BoQ7YfbXpZPY6pk3ksv/?imgmax=800)
![clip_image034 clip_image034](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1DuN8GbkdDFP0BdcqBNQ8Bo5m8yC6-rPihDb_vGAvTB5QLUbf4ckWI7CTMAnXeGxKbTesMLMy15oMR5XWARRQzeWQPNL6oTH53uxbZ3pulyu946wcl8mkb7TTJBJqy3JV2P79OGSSSyAh/?imgmax=800)
· Take the default option handling unspecified services and click Next.
![clip_image036 clip_image036](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTmdG-COzI2Du_m9PivvLjF9cFH8SPdV9jzt5CnC3uEYZgwi9TH4WtePSvG2YpEFLo54EYORco8LEO55Q4QrGf8DgQz1mMVbeH1AY0irtXFKPuNQt3NG_wtC8zClRpKS1umsBe-kWnRAFt/?imgmax=800)
· Review the following services as per the screenshots. (DNS client is now enabled so will not appear)
![clip_image038 clip_image038](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_WE693pzosuaV13EsvrVtGSO7hixt-5rPdnZNDAvPemA3sXxcU_nilzg_k-yc_HXZBRgtBJ7Ju-bo9P386wxow8tW-zZiSH-LQNKSzm1Wtr4fY88iJ8Evqwbagolvw45h78h_wdHi1Jc8/?imgmax=800)
![clip_image040 clip_image040](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_rj7EYdOs-5FR8tI-x2YKz78SSP72Ov_kGrxYRwY61WUvpToXR4rUIuenOC2s45xNXmKVORLRXpgOphAafVH4Y5eFHhm9imyIKwawfpTJ8zBKNg8tROqcfsZa7ro8khdxWKo5Y0CTtTc2/?imgmax=800)
![clip_image042 clip_image042](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7DlEHA5VfyK8I3j_P12fWdA-4PLNQBY0FH2prNiNfHarvXiRimJlM427UWkh_iOV4X30BYxceniIqokElJvDLeN98mCSVUflh6kRJtCRwMlRVWqhWUlaJH1_JJVxI0m13WfV6-rWbT52H/?imgmax=800)
![clip_image044 clip_image044](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiVP9_AzWmYLkKeruyqQuai-VGPfBBE1UO-6MwaVuZYBRhfcsFSSDCx_sdodld_-yL8MtbOZJbZE9OTHgQfFoF6Arnd4ufcfng49KmNHhFY-7LqY55Tj0NYQb7Ubko8YzCUKynsjKVQQ9M/?imgmax=800)
![clip_image046 clip_image046](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiJm9hPG9t4DAOfaVlotwb6JTXKV6OhbbJcG5LLmtjeNFOg-f5hr1fjyavSUE4YG8i58uRRXaZ6R6RPVt-E-uzvfviajlvPneElq2ixSv4DII0bEDLK4ctP6iN-fHLe6To2UKcnBiPhmLM/?imgmax=800)
![clip_image048 clip_image048](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhb9B5X2i7J-zAQLU7busuWSHPE-hUoholMJlDhjKI7XCgPEbk8kq_-GLLAiOr3gJx9gLTZNU6Sy2UBRO-x3z4FLJyaX-WTvhMHwRbxAD_HMFqp7G4WDHV0TG3-2v5h2VdmxqaLejc68VND/?imgmax=800)
![clip_image050 clip_image050](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidEb3ye9xEOK3XASz6cOGmDLQWzfDhSHsPEe-yYQ1hGiWwpNCnUrRimiWLGPj5zKfHa6RqLexi230lXu0eEU0Qf9-RW6zTdLmULJATXwXsH8JR70K3Wq2vel9cFLV8kStwwl2jAHbbK7l8/?imgmax=800)
· Select Skip this section and Next.
![clip_image052 clip_image052](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8h57SIw12rNP_OvzthHC9W_8xvCFMiVADk-DP-p7K1FTXd-NjnY198Vuyyvqta7__MZfst0ibVZDPKJ4F0URlgDb_1g1K3FiHL5K4ag_gRjPSSI48FmBs3fAlgEWGE6TmwJeL4v4eOJM3/?imgmax=800)
· On Registry setting click Next.
![clip_image054 clip_image054](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVKD3SLf_p8bTvti49Ckfyszsk7IVJIF9zriBt1esIB6L6S47pLEXcL5oO2DMwDDmS1nxvX2f1DkrpEdR2qzFTFn4flwr0yX5yW767ecfIYorXnq8v3SlFQCbohMIjw7cmzWMaSlIJh52l/?imgmax=800)
· Deselect - It has surplus processor capacity etc and click Next.
![clip_image056 clip_image056](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2uTNb1fj7D1ab-9nMzi8wPMozB1jY0_fry8Xx5brZ35JLI-NRQvviYK9evjPURSmX347T1BnqtgQ7YJtxF7jTZ4p3EpgaJCWjSvHfPXV8n2AFRKnsWIoDEJ-SkjkXC_9kBXTs_BunfF6-/?imgmax=800)
· Select Local Accounts on the remote computers option in addition to Domain Accounts and click Next.
![clip_image058 clip_image058](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhkVatTshT2Yh8o3UQZM3sKSOa1LdgDm44vKbekDuIdb1XWdoLwNqSTdGXCw6SSaR-FKCGftb8EPlt9X0kp1Yrqr6ysBEiciDBecuTnQsx49ZIiVx5bVni0g48Y8vpdzVCK7MpbSNw1e7cw/?imgmax=800)
· Take the default option on the next four screens and click Next four times.
![clip_image060 clip_image060](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBw1_17NxJ6qPEDEIbp6a2ez036BkHOfVHa-50v1G3WZwSJsBaI4BW4iH1NR-VW1dH3c46rAn4nj8hPLcD5GyE2DwdqTViN9kVj_oc8oOLmQ3Sd5QpKmwpKaX7tYA85Jmi6wlBdRUeENol/?imgmax=800)
![clip_image062 clip_image062](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAIDUdrzGRpWKueE5aoyn3ZTZJhoZflO8HScyuf_VBP5P_xzkAuPAsW7f3xD7S6Bu9a1FL_wvyZ2Dn6SY9Fkyxt60YtKgMk0zllW6U6h09aWiH40JozFChBJXREG45iJczF7pMvnItFD0K/?imgmax=800)
![clip_image064 clip_image064](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgyOcxpXPheXrNt5Sjlt8E8cXiHrAoanZbMoXjvlz_BuL8jxdIhPaovywHFCm1pEsnG4nskWOXE3PL7fnWZ9MRGFlS3KS8JoDclwFPoKkiyR2qeYGrXLJBX_jbIwZVf2M9vajRrfqO6m0ry/?imgmax=800)
![clip_image066 clip_image066](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsXfEKa7XjGjFtjeqgtwSSTrNb6NmAIcH5S4AwBHzzp5n6xkRiWJJ7FJqxj275Q7Z1K3ce5-Q4-JwNCglzltMZYMsVJ-4Vq5hflYgFm3awAirpcK4PNIJdFIcuorwFFFPDS1pOZYZfohNa/?imgmax=800)
· Select Audit successful and unsuccessful activities and click Next.
![clip_image068 clip_image068](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipSe1A5wpeAAkv-NeltEzY-_DWtJCsYRLhwdn8XK3ywGUu7kCd7QAAZsSU2c7NPOktYlPCDoAaYGbJr33zxUyvp9yhVlxMsOoCKs5TQRpziv5Cw48Oz5Px0q0Es1UqfgYVKXMFpINoOhTt/?imgmax=800)
· Deselect the option to include the SCWAudit.inf security template and click Next.
![clip_image070 clip_image070](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbGoA8FQt6gbZiTykk7ytkNoAcDCRIterhG_dG-YiRJvlsWLJ5ibxa4oiqP0mZ-zUtHsWUCMkLvuHAc1VAwkSWf1mdfeGQKg94EyIZajmE8UERKba8j0eDSu1lKEv2dUQeexMh9DpJD6jn/?imgmax=800)
· Click Next to save the policy.
![clip_image072 clip_image072](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEvon-IOQqoFGwwvg1jOZc82oSIMro0aeQdcrpkQn9o6pn-Ny_fnWwg76BKL13vxuUNgb3yUUjOccglQ9MWJyI2Li_wsuK0Ne9Y7hGA8jl-SQeqrHs35hTP1y4D1uUdW7NdTUSHPqgnlTc/?imgmax=800)
· Create the policy name OCS_Edge_SCW and click Next.
![clip_image074 clip_image074](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiErLHcHUnVW5lJDvwnFbuVlXhyphenhyphen7qGwkcm-au4UYKviH2Dbk8LdD4bvnn1Lu9S7CF8FlukvEwJF8ZhWKeS6UZH3Tqa6CwNhq59nrvruwmyO2uqD6OlepM63e9AGNPqu5pDw44kaGOhkpPwW/?imgmax=800)
· Click apply now and Next.
![clip_image076 clip_image076](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnnvYEXkWMQxhC1aeBCE_C9SPvJBEPH5A5F0Qoj6MLamSYu9cm97V31l9YV-4OTdEwd-gfTgHWVdCP9XA7OiIkdEMq4s1iaZ00bdpZ0yPYGAegXOXog2xsEi_eHj7ih9QFAl0NtS9DZCnd/?imgmax=800)
· Click Next once the policy has been applied
![clip_image078 clip_image078](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIbmqcKURYAGzyalPeoEg-8gVssicbH0utEgSEyERrbJOr-3VI2XBicS7mzccO1jHIrATO8u6WGIzQIAxhzP4ppo2QbyaW0eLP0fln4qLfAR7Y9oREK1SK2jgx-Y4vTiwFE-Qv0j5uBreB/?imgmax=800)
· Click Finish.
![clip_image080 clip_image080](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2aihgbYRblj3RdaALm6REzI8imEgfyxccdAyiqhOx8FbNf9qqK8Js80A7bUqadbf6JM_YALMYSxCd0p2DYm3xR5YTayZkv3AL36ECsDGoafbux76EC3XxlxxwAUlQ2vvHZD5tTRmSzY1r/?imgmax=800)